Releases: github/dependabot-action
Releases · github/dependabot-action
v3.0.0
v2.33.0
What's Changed
- Bump node from 20 to 24 by @Nishnha in #1688
- Add sbt dockerfile with image and sha by @AbhishekBhaskar in #1692
Full Changelog: v2...v2.33.0
v2.32.0
What's Changed
- Fix string comparison in bump-version script by @jeffwidman in #1638
- Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1643
- Bump the prod-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #1647
- Bump the dev-dependencies group with 3 updates by @dependabot[bot] in #1648
- Bump handlebars from 4.7.8 to 4.7.9 by @dependabot[bot] in #1644
- Bump lodash from 4.17.21 to 4.18.1 by @dependabot[bot] in #1650
- Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1653
- Bump dependabot/proxy from v2.0.20260404001356 to v2.0.20260406203606 in /docker in the dependabot-core-images group by @dependabot[bot] in #1654
- Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1655
- Bump dependabot/fetch-metadata from 2.5.0 to 3.0.0 by @dependabot[bot] in #1646
- Bump the dev-dependencies group across 1 directory with 4 updates by @dependabot[bot] in #1651
- Bump the dependabot-core-images group across 1 directory with 30 updates by @dependabot[bot] in #1656
- Set NODE_OPTIONS to increase V8 heap for large monorepos by @davidwinder-gyde in #1649
- Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1657
- Bump actions/create-github-app-token from 3.0.0 to 3.1.1 by @dependabot[bot] in #1658
- Bump the dependabot-core-images group in /docker with 29 updates by @dependabot[bot] in #1664
- Update proxy image by @robaiken in #1665
- Add missing ecosystems to automatic GitHub Packages auth by @JamieMagee in #1668
- Bump the dependabot-core-images group across 1 directory with 30 updates by @dependabot[bot] in #1669
- Bump the dependabot-core-images group across 1 directory with 30 updates by @dependabot[bot] in #1676
- Add updater container support for conda, deno, and nix by @Copilot in #1681
- Bump the dependabot-core-images group across 1 directory with 29 updates by @dependabot[bot] in #1679
- Bump protobufjs from 7.4.0 to 7.5.6 by @dependabot[bot] in #1680
- Bump the dev-dependencies group across 1 directory with 8 updates by @dependabot[bot] in #1682
- Bump the dependabot-core-images group in /docker with 32 updates by @dependabot[bot] in #1687
- Bump tar-stream from 3.1.8 to 3.2.0 in the prod-dependencies group across 1 directory by @dependabot[bot] in #1678
- Bump dependabot/fetch-metadata from 3.0.0 to 3.1.0 by @dependabot[bot] in #1670
- Bump dockerode from 4.0.10 to 5.0.0 by @dependabot[bot] in #1673
- v2.32.0 by @Nishnha in #1690
New Contributors
- @davidwinder-gyde made their first contribution in #1649
Full Changelog: v2...v2.32.0
v2.31.0
What's Changed
- Update image pull backoff params by @pavera in #1592
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251124194534 to v2.0.20251219172147 in /docker by @dependabot[bot] in #1596
- Bump the dependabot-core-images group in /docker with 28 updates by @dependabot[bot] in #1595
- Bump the dev-dependencies group across 1 directory with 8 updates by @dependabot[bot] in #1602
- Bump the prod-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #1598
- Bump actions/create-github-app-token from 2.2.0 to 2.2.1 by @dependabot[bot] in #1587
- Bump dependabot/fetch-metadata from 2.4.0 to 2.5.0 by @dependabot[bot] in #1597
- Bump eslint-plugin-github from 5.1.8 to 6.0.0 by @dependabot[bot] in #1438
- Bump the dev-dependencies group with 3 updates by @dependabot[bot] in #1604
- Bump @actions/core from 1.11.1 to 2.0.2 by @dependabot[bot] in #1605
- Bump globals from 16.5.0 to 17.1.0 by @dependabot[bot] in #1609
- Bump @types/dockerode from 3.3.47 to 4.0.1 by @dependabot[bot] in #1606
- elevate GITHUB_TOKEN to packages feed credential by @brettfo in #1603
- Update reference to Dependabot proxy by @JamieMagee in #1610
- Add precommit ghcr version and sha by @AbhishekBhaskar in #1621
- Pass through
OPENSSL_FORCE_FIPS_MODEenv var to containers by @jeffwidman in #1622 - Bump the dependabot-core-images group across 1 directory with 30 updates by @dependabot[bot] in #1623
- Add devcontainer config to pin Node version from .nvmrc by @Copilot in #1626
- Bump actions/create-github-app-token from 2.2.1 to 3.0.0 by @dependabot[bot] in #1632
- Bump minimatch from 3.1.2 to 3.1.5 by @dependabot[bot] in #1627
- Bump the dev-dependencies group across 1 directory with 8 updates by @dependabot[bot] in #1633
- Bump tar-stream from 3.1.7 to 3.1.8 in the prod-dependencies group across 1 directory by @dependabot[bot] in #1634
- Bump @types/node from 24.10.1 to 25.2.0 by @dependabot[bot] in #1617
- Bump the dependabot-core-images group in /docker with 30 updates by @dependabot[bot] in #1630
- Bump the dependabot-core-images group in /docker with 29 updates by @dependabot[bot] in #1637
- v2.31.0 by @jeffwidman in #1639
New Contributors
- @AbhishekBhaskar made their first contribution in #1621
- @Copilot made their first contribution in #1626
Full Changelog: v2...v2.31.0
v2.30.0
What's Changed
- remove unused output and repo path code by @jakecoffman in #1537
- Bump the dependabot-core-images group in /docker with 25 updates by @dependabot[bot] in #1516
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250804193157 to v2.0.20250826205840 in /docker by @dependabot[bot] in #1534
- add invocation of specific commands (graph) by @jakecoffman in #1540
- Pass OIDC environment variables to proxy by @JamieMagee in #1544
- Bump actions/create-github-app-token from 2.1.1 to 2.1.4 by @dependabot[bot] in #1538
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250826205840 to v2.0.20251003180402 in /docker by @dependabot[bot] in #1546
- Bump actions/setup-node from 4 to 5 by @dependabot[bot] in #1536
- Bump github/codeql-action from 3 to 4 by @dependabot[bot] in #1548
- Delete the custom CodeQL config in favor of default config by @jeffwidman in #1552
- add tenant-id and client-id to credentials by @brettfo in #1553
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251010195543 to v2.0.20251014173146 in /docker by @dependabot[bot] in #1554
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251014173146 to v2.0.20251015175503 in /docker by @dependabot[bot] in #1555
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251015175503 to v2.0.20251023141128 in /docker by @dependabot[bot] in #1557
- Adding Julia to actions by @robaiken in #1558
- Adding Bazel to actions by @robaiken in #1560
- Extract the updater image's SHA from the input parameters and pass it as an envvar by @brrygrdn in #1561
- Bump actions/setup-node from 5 to 6 by @dependabot[bot] in #1556
- Bump on-headers, compression and morgan by @dependabot[bot] in #1565
- Bump the prod-dependencies group across 1 directory with 2 updates by @dependabot[bot] in #1539
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251023141128 to v2.0.20251107162748 in /docker by @dependabot[bot] in #1563
- Adding OpenTofu image by @robaiken in #1566
- Bump the dev-dependencies group across 1 directory with 16 updates by @dependabot[bot] in #1570
- Bump eslint-plugin-jest from 28.11.0 to 29.2.1 by @dependabot[bot] in #1579
- Bump actions/create-github-app-token from 2.1.4 to 2.2.0 by @dependabot[bot] in #1574
- Bump actions/checkout from 5 to 6 by @dependabot[bot] in #1573
- Bump jest-circus from 29.7.0 to 30.2.0 by @dependabot[bot] in #1577
- Bump @types/node from 22.15.21 to 24.10.1 by @dependabot[bot] in #1578
- Bump the dev-dependencies group with 4 updates by @dependabot[bot] in #1575
- Set check-dist workflow permissions by @Nishnha in #1581
- Set test workflow permissions by @Nishnha in #1582
- Bump the dev-dependencies group with 2 updates by @dependabot[bot] in #1584
- Bump node-forge from 1.3.1 to 1.3.2 by @dependabot[bot] in #1583
- Bump jest and @types/jest by @dependabot[bot] in #1576
- Bump @actions/http-client from 2.2.3 to 3.0.0 by @dependabot[bot] in #1569
- Update README.md to add deploy instructions by @honeyankit in #1429
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20251113195050 to v2.0.20251124194534 in /docker by @dependabot[bot] in #1580
- Bump the dependabot-core-images group in /docker with 28 updates by @dependabot[bot] in #1572
New Contributors
Full Changelog: v2.29.0...v2.30.0
v2.29.0
What's Changed
- credential type is not a secret by @jakecoffman in #1517
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250618164131 to v2.0.20250701191801 in /docker by @dependabot[bot] in #1511
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250715192211 to v2.0.20250716173616 in /docker by @dependabot[bot] in #1518
- handle NPM metadata missing registry key by @jakecoffman in #1519
- extract registry from url for other ecosystems by @jakecoffman in #1520
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250716173616 to v2.0.20250717140017 in /docker by @dependabot[bot] in #1521
- remove automerge by @jakecoffman in #1515
- set index-url from url by @jakecoffman in #1522
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250717140017 to v2.0.20250724172018 in /docker by @dependabot[bot] in #1525
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250724172018 to v2.0.20250731100605 in /docker by @dependabot[bot] in #1527
- Add path to npm registry definition by @pavera in #1531
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250731100605 to v2.0.20250804193157 in /docker by @dependabot[bot] in #1529
- Bump actions/create-github-app-token from 2.0.6 to 2.1.1 by @dependabot[bot] in #1533
- Bump actions/checkout from 4 to 5 by @dependabot[bot] in #1532
- Updating updater images to the version 20250904090707 by @thavaahariharangit in #1535
Full Changelog: v2...v2.29.0
v2.28.0
What's Changed
- fix 403s, registry creds probably not needed by @jakecoffman in #1498
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250602172812 to v2.0.20250618164131 in /docker by @dependabot in #1501
- generate credentials metadata by @jakecoffman in #1502
- Use Registry Credentials when passed to env by @jurre in #1497
- Run
update-ca-certificatesasrootby @JamieMagee in #1505 - Bump the dependabot-core-images group in /docker with 23 updates by @JamieMagee in #1508
- Add
vcpkgandrust-toolchainecosystem support by @JamieMagee in #1509 - Bump the dependabot-core-images group in /docker with 25 updates by @dependabot in #1513
- v2.28.0 by @jakecoffman in #1514
Full Changelog: v2...v2.28.0
v2.27.0
What's Changed
- Bump the dependabot-core-images group in /docker with 23 updates by @dependabot in #1453
- Bump tar-fs from 2.1.2 to 2.1.3 in the npm_and_yarn group by @dependabot in #1489
Full Changelog: v2.26.0...v2.27.0
v2.26.0
What's Changed
- Bump eslint-import-resolver-typescript from 3.8.3 to 4.2.2 by @dependabot in #1439
- Remove unnecessary hardcoding of
refby @jeffwidman in #1456 - Enable caching of
npm install/npm ciforsetup-nodeaction by @jeffwidman in #1457 - fix detached head state on push by @jakecoffman in #1464
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250404141843 to v2.0.20250425201519 in /docker by @dependabot in #1465
- Bump dockerode from 4.0.5 to 4.0.6 in the prod-dependencies group by @dependabot in #1460
- Bump @actions/github from 6.0.0 to 6.0.1 in the prod-dependencies group by @dependabot in #1471
- Bump dependabot/fetch-metadata from 2.3.0 to 2.4.0 by @dependabot in #1470
- Bump the dev-dependencies group across 1 directory with 14 updates by @dependabot in #1468
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250501191828 to v2.0.20250510074035 in /docker by @dependabot in #1472
- Update certificate to support python 3.13 by @thavaahariharangit in #1475
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250510074035 to v2.0.20250515192846 in /docker by @dependabot in #1477
- Switch from PAT to federated secret for pulling ghcr images by @jeffwidman in #1478
- Bump commander from 13.1.0 to 14.0.0 by @dependabot in #1480
- Bump lint-staged from 15.5.2 to 16.0.0 by @dependabot in #1473
- Switch to using an App token instead of a PAT by @jeffwidman in #1442
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250515192846 to v2.0.20250521082831 in /docker by @dependabot in #1482
- add a manually run build workflow by @jakecoffman in #1486
- Bump the dev-dependencies group across 1 directory with 9 updates by @dependabot in #1485
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250521082831 to v2.0.20250522155011 in /docker by @dependabot in #1483
- Bump undici from 5.28.5 to 5.29.0 in the npm_and_yarn group by @dependabot in #1476
- Bump actions/create-github-app-token from 1.11.6 to 2.0.6 by @dependabot in #1484
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250522155011 to v2.0.20250602172812 in /docker by @dependabot in #1490
- v2.26.0 by @thavaahariharangit in #1491
Full Changelog: v2...v2.26.0
v2.25.0
What's Changed
- Implement feature to capture metrics inside Dependabot Actions to post to Dependabot API by @honeyankit in #1428
- Adding helm ecosystem image by @robaiken in #1430
- Bump commander from 12.1.0 to 13.1.0 by @dependabot in #1398
- Bump the dev-dependencies group across 1 directory with 5 updates by @dependabot in #1434
- Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250310190033 to v2.0.20250320211425 in /docker by @dependabot in #1433
- Bump the dependabot-core-images group in /docker with 23 updates by @dependabot in #1432
- Bump eslint from 8.57.0 to 9.22.0 by @dependabot in #1424
- Make typescript compile to
"es2022"by @jeffwidman in #1435 - Remove deprecated command invocation by @jeffwidman in #1436
- Remove unused
fetch-metadatastep by @jeffwidman in #1441 - Bump github/dependabot-update-job-proxy/dependabot-update-job-proxy from v2.0.20250320211425 to v2.0.20250404141843 in /docker by @dependabot in #1448
- Bump dockerode from 4.0.4 to 4.0.5 in the prod-dependencies group by @dependabot in #1445
- Bump the dependabot-core-images group in /docker with 23 updates by @dependabot in #1451
- Bump the dependabot-core-images group in /docker with 23 updates by @dependabot in #1452
- v2.25.0 by @jakecoffman in #1454
Full Changelog: v2...v2.25.0